Sednit reloaded: Back in the trenches
ID: d19a1242-8203-53d8-b790-884a2f9792e7
STIX ID: report--d19a1242-8203-53d8-b790-884a2f9792e7
Feed Name: WeLiveSecurity (ESET Research)
Since April 2024 ESET documents the reactivation of Sednit’s advanced implant development, showing a dual-implant espionage strategy using BeardShell (PowerShell-based C2 via Icedrive) and a heavily modified Covenant (cloud-backed .NET implant using Filen/pCloud/Koofr), alongside a SlimAgent keylogger derived from Xagent. The report links these tools to Sednit’s 2010-era code through unique obfuscation and implementation artifacts, provides IoCs and MITRE mappings, and notes active use against Ukrainian military targets including exploitation of CVE-2026-21509.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
